Database/Firmware, BMC & network fabric

Insyde InsydeH2O (PnpSmm parameter buffer, DMA TOCTOU): The plug-and-play SMI handler's parameters can be swapped
Impact
The plug-and-play SMI handler's parameters can be swapped by DMA between the check and the use. PnpSmm is the driver that writes SMBIOS/platform-description data, so corrupting it lets an attacker both corrupt SMRAM and poison the hardware inventory the OS and your fleet-management tooling read back - a node can be made to misreport what it is.
Who can reach it
An attacker able to drive DMA at host memory while the SMI handler is mid-flight - a malicious PCIe device, a peripheral running attacker-flashed firmware (NIC, GPU, NVMe), or a tenant with a passed-through device that is not behind a correctly configured IOMMU. Notably does NOT require host root, which is what separates this family from the ordinary SMM callout bugs.
What to do
Firmware flash from the server OEM, not from Insyde - the fixed Insyde kernel has to be rebased by Dell/HPE/Lenovo/Supermicro and re-qualified before it reaches you, which for this batch ran months behind Insyde's own release. One reboot per node, so schedule it against a GPU drain. Fixed in kernel 5.2 / 05.27.29, 5.3 / 05.36.25, 5.4 / 05.44.25, 5.5 / 05.52.25. The compensating control that actually works here is the IOMMU, and Insyde says so in the advisory: enable VT-d/AMD-Vi with pre-boot DMA protection so the ACPI runtime buffer the handler reads is not reachable by an untrusted device. That is a BIOS setting, deployable fleet-wide without a flash, and it should be on already on any node that passes devices through to tenants. Patch the batch, not the CVE - Insyde filed one advisory per driver for the same defect, so fixing this one leaves every sibling handler reachable.
References
Related entries
- Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU): Firmware Volume Block services are the abstractionCVE-2022-31243 · Insyde InsydeH2O (FvbServicesRuntimeDxe input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU): A DMA race against the Platform Configuration Database SMICVE-2022-32266 · Insyde InsydeH2O (PcdSmmDxe parameter buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU): The sharpest irony in the batch: SmmResourceCheckDxeCVE-2022-32267 · Insyde InsydeH2O (SmmResourceCheckDxe input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (FwBlockServiceSmm input buffer, DMA TOCTOU): The firmware block service is the SMM-side writerCVE-2022-33906 · Insyde InsydeH2O (FwBlockServiceSmm input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (IdeBusDxe SMI input buffer, DMA TOCTOU): SMRAM corruption via a DMA race on the legacy IDE/ATA busCVE-2022-33907 · Insyde InsydeH2O (IdeBusDxe SMI input buffer, DMA TOCTOU)Medium
- Insyde InsydeH2O (Int15ServiceSmm parameter buffer, DMA TOCTOU): DMA race against the legacy INT15 services SMI handlerCVE-2022-33982 · Insyde InsydeH2O (Int15ServiceSmm parameter buffer, DMA TOCTOU)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.